Using Firebug to “profile” a web site

Firefox has long been much more “open” at allowing you to see everything a web server is doing (things like not allowing a web site to disable right click without your permission).

Firefox has an addon called Firebug that is extremely helpful and interesting.   It may be a little on the geeky side, but even if you aren’t a geek, you can still see a lot of useful information.

To use it:

Install Firefox browser if you don’t already have it:  Firefox

Install the Firebug addon:   Firebug

Turn on Firebug from the Tools menu in Firefox

Go to a web page and press F12

See all the Sekrit stuff the evil web site is doing….    If you go to

http://streamingradioguide.com/streaming-radio-stations.php?formatid=1 

the what’s on now page, you’ll see that my web site doesn’t cause your browser to do anything unexpected:

every single request goes to my web server.   The page downloads completely in a little over 2 seconds.    It starts to load the web page, sees I use a .css style sheet, and then starts to see I have about 25 different graphics, which my server returns in parallel.   The “sneakiest” thing it does is near the end it loads up countdown.js, which is a javascript thing that was counting down the number of seconds until May 21, 2011 and the Rapture.

Now let’s compare that to a “free” ustream player:

This is only the first page…   Translating the Webspeak into English of who uStream has told that you’re watching that stream:

  • Facebook (even if you don’t use Facebook)
  • Twitter
  • Quantserve.com   (a web site traffic measuring service)
  • scorecardresearch.com  (Market Research)
  • google-analytics.com  (to serve up Google ads)
  • d.ustream.tv – a sneaky backdoor method to reach Openx
  • openx.com – surprise surprise surprise!
  • imrworldwide.com – Nielson Net Ratings
  • paypal.com (!)
  • conviva.com – Video Ad monetization
  • adap.tv – Global Video advertising
  • lphbs.com – an anonymous domain whose purpose seems to be to subvert Adobe Flash cookie cross-domain policy limitations
  • turn.com – Digital advertising
  • brainient.com  – video pre-roll advertising
  • w55c.net  – DataXu  – “advertising at the speed of life” 
  • wtp101.net – Godaddy server hiding behind domain proxy registration
  • titaltv.com – another Video ad company
    (It’s looking like we may have a real time auction going for people buying your attention)
  • mmismm.com – meebo –  web site sharing service 
  • adadvisor.net – Targus – buyer tracking
  • exelator.com – eXelate – another advertiser tracking service
  • bluekai.com  –   gather 3rd party audience data in realtime 
  • doubleverify.com –  advertising fraud detection  
  • rfihub.com – Rocket Fuel – data driven targeted advertising 
  • doubleclick.net – long time ad server network
  • vindcosuite.com  (typo?)
  • adotub.com    (typo?)
  • analogdemographics.com – “behavioral targeting data aggregation”
  • brllg.com –
  • brooklyndb.com – another domain hidden behind a proxy registrar – related to amazonaws.com
  • amazonnaws.com – Amazon
  • 2mdn.net   (wants to write flash cookies to your browser)
  • rlcdn.com – Rapleaf – “we want every person to have a meaningful, personalized online experience” – offers an “opt out” except of course you never knew you opted in

The result is close to 3 million bytes of traffic and over 30 different sites being told what you’re doing (and those sites can pass it on to others without your knowledge)

So what would you like me to do about this?

This entry was posted in About the Guide. Bookmark the permalink.

10 Responses to Using Firebug to “profile” a web site

  1. Parrott says:

    Hey Art: Do those third parties see my IP address? So they are seeing 373.373.902.56(made up IP address) is visiting Ustream? Or what all are they looking for?
    Hmmmmm
    Parrott

    • Art Stone says:

      Absolutely. That’s the least of what they were told.

      For srtarters, they use Flash Cookies. Those are separate from regular cookies that you can block or clear. If you turn off Flash Cookies, the stream wil not start.

      I haven’t “reverse-engineered” any of the stuff. The Wall Street Journal did a piece on spying techniques maybe six months ago.. Beacons, persistent javascript, flash cookies, and stuff we probably don’t even know about unless you do a packet level trace (which is what their consultant did). It’s a reasonable assumption that everyone on that list knows your age, your zip code, your gender, your likely income, how many children you have, what web sites you visit and your email address.

      Congress has been threatening to create a law to prevent this crap – and only alllow marketers to track you from site to stie with your consent (being logged into Google Mail or Facebook would probably be considwred consent).

  2. Parrott says:

    Bummer. Hate to hear that. You know I hadn’t heard of Flash-cookies.
    I wonder if ‘ Liquidcompass’ is as bad? I kinda like that one cause it loads faster .
    Thanks Art.

    • TheChairman says:

      Awhile back, I posted a link to the page where you can change Flash Player settings. (yes, you must do it online via Adobe’s site… sneaky, eh?).

      Also, by default Flash enables your microphone and camera!

      Here’s the link to change your Flash Player settings:

      http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager02.html

      Furthermore, those insidious Flash cookies are buried deep in your directory structure… here’s the location on a Windows 7 machine:

      C:\Users\%USERNAME%\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys

      Make a shortcut to the folder and routinely delete everything EXCEPT ‘settings.sol’

      • Art Stone says:

        One of the “abuses” uncovered by the WSJ is that these networks reconstruct the tracking for each other. They’ll use multiple methods and if you clean out one method, the other methods will just reconstruct the stuff you deleted.

        Google is the hardest to shake. If you use gmail, you generally stay logged in so you get notified of new mail or just don’t want to login and out over and over. Logging out doesn’t remove the tracking. Google analytics and Google ads are everywhere (a site may run the analytics without hosting ads) so google sees almost everything you do

        Facebook and linkedin are probably more dangerous in the long run – they directly know a lot about you that Google only knows by inference… Although Google is probably more smart enough to connect all of it.

      • Parrott says:

        Hey Chairman, I run XP on this machine. It looks like that directory you are talking about is in
        C:\Documents and Settings\(username)\Application Data\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdn.gigya.com\settings.sol

        There is a separate directory for each one of those Like #chase.com , another one was #LLBean.com. Its every one either me or my wife has been too. Each one of those directories has a settings.sol. I generally clear out the C:\Documents and Setting\Username\Temp and Temporary Internet files. But I didn’t know that stuff was there. should I delete them ? why not delete settings.sol ? make a directory of those and it can’t copy them back in.

        • TheChairman says:

          Flash cookies (aka ‘folders’) start with a ‘#’ char.

          Each ‘container’ for a given cookie looks like a folder in File Explorer and may have a ‘settings.sol’ file.

          I think you’re drilling down one level too deep… when you open any folder which begins with ‘#’ you are actually opening the cookie for that site (be careful, malicious cookies will launch a browser and take you to the site and start installing all sorts of nasty stuff).

          Stay up one level: …\flashplayer\sys\

          If you’ve configured Flash via the Adobe site, then you only need to preserve one file to keep your settings:

          …\flashplayer\sys\settings.sol

          Wipe anything else which begins with ‘#’

        • TheChairman says:

          Another place Flash cookies are stored (Win 7):

          C:\Users\%USERNAME%\AppData\Roaming\Macromedia\Flash Player\#SharedObjects

          Drill down into the above folder to find more cookies.

    • Art Stone says:

      I admit to being conflicted on the subject of tracking. Just before I went to be with John Galt in April, I changed the tracking here to be opt out by default, which is one of the proposals floating in Congress. This web site would be not 10% as valuable if I didn’t track usage to show which shows and stations are the most popular.

      Tracking on the Internet is not that different from the mail order catalog, magazine or charity businesses. If you buy something from one catalog, you start getting 5 new catalogs. If you give to a charity, 5 other similar charities start calling you asking for money. If you give money to a political campaign, they start asking for money for the rest of your life.

      It’s annoying, but I’m not sure I want the Federal government stopping it.

  3. Art Stone says:

    I wonder if anyone has ever thought of offering a spyware free DNS server like Google’s 8.8.8.8

    So when your browser tries to load in a JavaScript file from a third party, the domain won’t resolve. You can do that with your “hosts” file “, but you have to maintain it

    Food for thought – if you use 8.8.8.8 as your DNS server, Google gets a lot of information about your activities.

Leave a Reply